DocumentCode
568718
Title
Testing and validating activity models for network intrusion detection
Author
Määttä, Marko ; Räty, Tomi
Author_Institution
VTT Tech. Res. Centre of Finland, Oulu, Finland
Volume
2
fYear
2012
fDate
12-14 June 2012
Firstpage
723
Lastpage
728
Abstract
Models and modelling are effective approaches to describe events or activities of systems or environment. An error or design flaw in the models can cause failures in applications utilizing these models. Therefore, an effective testing and validation approach is required for identifying possible errors and misunderstandings. This paper proposes a process for testing and validating intrusion models used in network intrusion detection. The process can be integrated as part of the intrusion model development process with proper tool support. This will help to identify possible errors in the intrusion model as early as possible. The contribution is to apply well-known aspects from software testing and implement them in the intrusion model testing and validation. The experimental implementation of the proposed process will concentrate on testing intrusion models focusing on detecting port scan attacks. This experiment will indicate that when the testing and validation is part of the intrusion model development process, the intrusion model developer receives immediate feedback and can quickly refine the intrusion model. This increases the confidence of the intrusion model and errors and design misunderstandings are located effectively.
Keywords
computer network security; program testing; activity model testing; activity model validation; intrusion model development process; intrusion model testing; intrusion model validation; network intrusion detection; port scan attack detection; software testing; Testing; Intrusion model; network intrusion detection; testing; validation;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer & Information Science (ICCIS), 2012 International Conference on
Conference_Location
Kuala Lumpeu
Print_ISBN
978-1-4673-1937-9
Type
conf
DOI
10.1109/ICCISci.2012.6297122
Filename
6297122
Link To Document